Secure by Design: Building Security into Engineering Workflows and Teams

QCon London 2025

Session

Secure by Design: Building Security into Engineering Workflows and Teams

Tuesday Apr 8 / 10:35AM BST, Mountbatten (6th Fl.)

Abstract

Security doesn't have to be a blocker- it can be an enabler. In this session, we’ll explore how to seamlessly integrate secure development practices into engineering workflows while fostering a culture of collaboration and shared ownership. From integrating security into IDEs, build pipelines, and CI/CD workflows to empowering developers with real-time vulnerability detection, we’ll showcase practical strategies to make security second nature for your team.

But secure development is about more than just tools - it’s about people. We'll discuss how to break down silos between developers and security teams, embed security champions in your organization, and leverage engaging, gamified training to build confidence and capability in secure coding practices.

Walk away with actionable insights to shift security left, enable your team to innovate without fear, and create workflows that blend security seamlessly into everyday development. Let’s build software that’s secure by design - together.

Interview

My work focuses on making security an integrated, empowering part of the software development process. I believe security should be woven into every stage of development - not something that slows things down, but something that enables teams to build with confidence. I help organizations create workflows where security is seamless, accessible, and collaborative, empowering both developers and security teams to thrive together.

The motivation for my talk is simple: security shouldn't be a roadblock - it should be an enabler of innovation. I want to show how we can build security into development workflows without stifling creativity. By fostering collaboration and breaking down silos between teams, we can make secure coding practices a natural, everyday part of development. It's about equipping teams with the tools, knowledge, and confidence they need to build secure software without hesitation.

This talk is for anyone who wants to make security a natural part of their development process. Whether you’re a developer, a security professional, or a team leader, this talk will help you understand how to bring security into your workflows in a way that feels empowering, not restrictive. It’s for anyone ready to shift their mindset and embrace a collaborative approach to building secure software.

I want attendees to leave feeling confident that security can be part of their daily development practice. They’ll take away practical strategies for integrating security into their workflows, from real-time vulnerability detection to breaking down barriers between development and security teams. Most importantly, I want them to feel inspired to build secure software from the ground up - confidently and without compromise.

The next big disruption in software will be the widespread integration of AI and automation into every part of the development lifecycle. From code generation to automated testing and even security vulnerability scanning, AI will streamline and accelerate development, enabling teams to focus on higher-level innovation while letting machines handle the repetitive tasks.

One of the most interesting things I learned at a previous QCon was the power of informal conversations between speakers and attendees during breaks. It’s always fascinating to hear directly from others about the challenges they’re facing and the innovative ways they’re approaching solutions. I also love discussing past sessions with other speakers—particularly the architecture track on the main stage, which is always a hot topic. The exchange of ideas and insights during these moments really adds depth to the overall conference experience.

76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon London 2025 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 8 April

10:35 Mountbatten (6th Fl.) Session Secure by Design: Building Security into Engineering Workflows and Teams Stefania Chaplin Founder & CEO @DevStefOps, Previously Solutions Architect @GitLab, AWS Certified Security - Speciality 11:45 Mountbatten (6th Fl.) Session open source Empower Your Developers: How Open Source Dependencies Risk Management Can Unlock Innovation Celine Pypaert Vulnerability Manager @Johnson Matthey, Women in CyberSecurity UK Volunteer, Book Contributor, Ex-Microsoft 13:35 Mountbatten (6th Fl.) Session software supply chain Trust No One: Securing the Modern Software Supply Chain with Zero Trust Emma Yuan Fang Senior Cloud Security Architect @EPAM, DevSecOps, Cloud Security Advocate, Strategist and Public Speaker, Ex-Microsoft, CISSP 14:45 Windsor (5th Fl.) Session Panel: Security Against Modern Threats 15:55 Windsor (5th Fl.) Session security Securing AI Assistants: Strategies and Practices for Protecting Data Andra Lezza OWASP London Chapter Leader, 10+ Years of Experience Building AppSec Program 17:05 Rutherford (4th Fl.) Unconference Unconference: Resilient Engineering Practices for Security Against Modern Threats